Apache Airflow vulnerabilities
143 known vulnerabilities affecting apache/airflow.
Total CVEs
143
CISA KEV
2
actively exploited
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL13HIGH40MEDIUM87LOW3
Vulnerabilities
Page 8 of 8
CVE-2026-32690P4LOWCVSS 3.7≥ 3.0.0, < 3.2.02026-04-18
CVE-2026-32690 [LOW] CWE-668 CVE-2026-32690: Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked.
If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0 that has the fix implemented
nvd
CVE-2026-40963P4LOWCVSS 3.1≥ 3.0.0, < 3.2.22026-06-01
CVE-2026-40963 [LOW] CWE-285 CVE-2026-40963: The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Da
The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking whether the caller had read permission on those linked Dags. An authenticated UI/API user authorized for one Dag could enumerate linked Dag IDs and dependency metadata for other Dags they were not authorized to read. Affects deploymen
nvd
CVE-2026-45426P4LOWCVSS 3.1≥ 3.0.0, < 3.2.22026-06-01
CVE-2026-45426 [LOW] CWE-863 CVE-2026-45426: Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log
Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued for at least one Dag. Apache Airflow's Log server authorized JWT tokens against Dag IDs by applying Python's `str.lstrip()` to the requested path segment when verifying the JWT's `sub` claim. `str.lstrip()` strips any of a *set* of cha
nvd
← Previous8 / 8